# Is there up-to-date documentation for implementing a custom Elasticsearch realm?

**URL:** <https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 30, 2020, 7:18pm UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367 "2020-06-30T19:18:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![TimothyMDean](https://avatars.discourse-cdn.com/v4/letter/t/6bbea6/32.png) [@TimothyMDean](https://discuss.elastic.co/u/TimothyMDean)\
**Post date:** [June 30, 2020, 7:18pm UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367/1 "2020-06-30T19:18:34Z")

</div>

Hello,

I am trying to implement a custom authentication realm for Elasticsearch, as documented at [https://www.elastic.co/guide/en/elasticsearch/reference/current/custom-realms.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/custom-realms.html). I think I understand the basics, but I suspect there's some version differences between what I see in the documentation and what I'm able to get building.

Specifically, I followed the link to the [sample custom realm](https://github.com/elastic/elasticsearch/blob/7.8/x-pack/qa/security-example-spi-extension/src/main/java/org/elasticsearch/example/realm/CustomRealm.java) and tried to implement an extension of the `org.elasticsearch.xpack.core.security.authc.Realm` class. According to the sample code, I should be implementing a method with this signature:

```auto
public void authenticate(AuthenticationToken authToken, ActionListener<AuthenticationResult> listener)

```

But when I try to compile my code against the appropriate Elasticsearch jar files, it appears that it is instead expecting this signature:

```auto
public User authenticate(AuthenticationToken token)

```

There are other methods with similar signature mismatches as well. My assumption is that my build is using an old version of the `org.elasticsearch.xpack.core.security.authc.Realm` class but I have been unable to confirm or correct the issue. I am building with Gradle, and the only way I seem to express my dependency on these classes is this:

```auto
compileOnly group:'org.elasticsearch.plugin', name:'x-pack-api', version: '5.6.1'

```

So clearly this is an old version of X-pack that doesn't seem to line up with current versions of Elasticsearch. But I can't seem to find newer release of the x-pack-api jar, nor can I find the classes it defines (including `org.elasticsearch.xpack.core.security.authc.Realm`) in any other Elasticsearch-provided jar file.

What am I missing here? Is there documentation somewhere that describes what ES jar files I should depend on to create a custom realm? Or is the sample code in the above link out of date?

Thanks in advance for any help you can provide...

---

<div class="post-metadata">

**Author:** ![TimothyMDean](https://avatars.discourse-cdn.com/v4/letter/t/6bbea6/32.png) [@TimothyMDean](https://discuss.elastic.co/u/TimothyMDean)\
**Post date:** [July 1, 2020, 3:50pm UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367/2 "2020-07-01T15:50:00Z")

</div>

I have found one clear disconnect between the official documentation and the sample implementation. The documentation [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/custom-realms.html#custom-realms) says that the realm to be implemented should extend the `org.elasticsearch.xpack.security.authc.Realm` class, but the sample code it links to actually extends the `org.elasticsearch.xpack.core.security.authc.Realm` class. The `core` part of the package name was added. I presume that the `org.elasticsearch.xpack.core.security.authc.Realm` is the newer and correct version of what we should be using under Elasticsearch 7.8?

Assuming that is true, I would appreciate any information on where I can get a jar file with this class and other related classes that are part of the X-pack core module. Is that published to a public repository somewhere?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 1, 2020, 11:40pm UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367/3 "2020-07-01T23:40:04Z")

</div>

To build custom realms for current version of Elasticsearch, you need the following two dependencies:

```auto
compileOnly("org.elasticsearch:elasticsearch:$version")
compileOnly("org.elasticsearch.plugin:x-pack-core:$version")

```

The 2nd one is where you will find the `Realm` class.

---

<div class="post-metadata">

**Author:** ![TimothyMDean](https://avatars.discourse-cdn.com/v4/letter/t/6bbea6/32.png) [@TimothyMDean](https://discuss.elastic.co/u/TimothyMDean)\
**Post date:** [July 2, 2020, 3:34pm UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367/4 "2020-07-02T15:34:41Z")

</div>

@Yang_Wang

Thank you for the response. Just so I understand - can you clarify where these jar files are published to? It doesn't appear that the `org.elasticsearch.plugin:x-pack-core` dependency is published to Maven central - Is that correct?

And is there any documentation that shows the current way to implement a custom realm? Or is the sample code the only current point of reference we can use?

Thanks

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 3, 2020, 1:09am UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367/5 "2020-07-03T01:09:03Z")

</div>

The artefacts are published to elastic's maven repoistory and you can reference it in Gradle like the follows:

```auto
repositories {
    jcenter()
    maven(url = "https://artifacts.elastic.co/maven")
}

```

Unfortunately, the documentation is indeed falling behind. I have openned an [issue](https://github.com/elastic/elasticsearch/issues/58985) to address it. For the time being, the sample code is the best and most accurate reference. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2020, 1:09am UTC](https://discuss.elastic.co/t/is-there-up-to-date-documentation-for-implementing-a-custom-elasticsearch-realm/239367/6 "2020-07-31T01:09:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
